I have a project that is using Active Directory Federation Services and doesn't have any of the HSTS settings. ADFS is a single sign on service from MS. It's a pre-canned service that runs an inclusive web server (not IIS). The site is redirected from NetScalers over SSL. ADFS will only answer on specified URLs.
Here's a write up from MS: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-faq
Is it possible to get a waiver or have the server excluded from being scanned?
I have a project that is using Active Directory Federation Services and doesn't have any of the HSTS settings. ADFS is a single sign on service from MS. It's a pre-canned service that runs an inclusive web server (not IIS). The site is redirected from NetScalers over SSL. ADFS will only answer on specified URLs.
Here's a write up from MS: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-faq
Is it possible to get a waiver or have the server excluded from being scanned?